Back to skill

Security audit

patent-pre-evaluation-report

Security checks across malware telemetry and agentic risk

Overview

This is a coherent patent pre-evaluation report skill that uses disclosed PatSnap MCP searches and writes a local HTML report, with credential-handling caveats for users.

Before installing, confirm you are comfortable sending patent-search inputs to PatSnap/智慧芽 MCP services. Keep unpublished invention details minimized where possible, follow the skill's confidentiality guidance, and store API keys only in your MCP client's secure configuration or environment, never in prompts, shared documents, or source control.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
The README instructs users to obtain and configure API Keys for external MCP services but provides no guidance on protecting those credentials, such as avoiding pasting keys into shared chat contexts, committing them to repositories, or exposing them in client logs/screenshots. In a skill that depends on third-party service connectivity, this omission increases the risk of accidental credential leakage and downstream unauthorized access to the PatSnap account or associated data/services.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.